Showing posts with label California Privacy Act. Show all posts
Showing posts with label California Privacy Act. Show all posts

Thursday, May 18, 2023

Tennessee Is State Number Eight to Pass a Privacy Law

On May 11, 2023, Governor Bill Lee signed the Tennessee Information Protection Act ("TIPA"). The Volunteer State is the third to adopt a comprehensive data privacy statute in 2023 (after Indiana and Iowa) and the eighth overall (joining the Golden State's California Consumer Privacy Act and California Privacy Rights Act and similar-yet-unique laws passed in Virginia, Colorado, Connecticut, and Utah).

As I cautioned in a March 2021 Perspectives from FSF Scholars, multiple, inconsistent state laws inevitably will lead to "[c]ounterproductive consumer confusion, along with unreasonably burdensome and unjustifiably costly compliance obligations." At that time, just two states – California and Virginia – had enacted legislation. Today, with that total rapidly approaching double digits, such concerns exponentially are greater.

Consumer rights established by the TIPA include the right to know that a covered entity is processing personal information; to access, correct, delete, and obtain a copy of that data; and to opt out of the sale of personal information. In addition, a covered entity must disclose, upon request, categorical information regarding personal information that was sold, and obtain a consumer's consent before processing "sensitive data."

Covered entities ("controllers") that share personal information with third parties ("processors") must include certain provisions in their contracts to protect these consumer privacy rights. Controllers also must conduct data protection assessments under certain circumstances (for example, if they engage in targeted advertising, process "sensitive data," or sell personal information).

The TIPA does not create a private right of action. The Attorney General is responsible for enforcing its provisions. Covered entities have 60 days to cure an alleged violation.

Perhaps most notably, the TIPA requires that covered entities "create, maintain, and comply with a written privacy program that reasonably conforms to the National Institute of Standards and Technology (NIST) privacy framework entitled 'A Tool for Improving Privacy through Enterprise Risk Management Version 1.0.'"

The TIPA becomes effective on July 1, 2024.

Friday, May 05, 2023

Seven States and Counting: Indiana Passes Privacy Law

Activity at the state level continues to complicate further the overall privacy landscape. On May 1st, Indiana Governor Eric Holcomb signed into law Senate Bill 5 (S.B. 5), the Indiana Consumer Data Privacy Act (ICDPA). Indiana is the second state to pass a comprehensive data privacy law in 2023 (Iowa was the first, as I noted in a recent post to the Free State Foundation blog) and the seventh overall (after California, not once but twice, Virginia, Colorado, Connecticut, Utah, and the aforementioned Iowa).

Meanwhile, Montana and Tennessee could follow quickly: bills in both states have made it to their respective governor's desks.

Uniquely, and apparently to provide an opportunity to learn how similar (but by no means identical) statutes in other states fare, the ICDPA will not go into effect until July 1, 2026. (Currently, only the laws enacted in California and Virginia are in force. The big day in Colorado and Connecticut is July 1st of this year, in Utah it is December 31st, and in Iowa it is January 1, 2025.)

Based largely (though, again, not entirely) on the Virginia Consumer Data Protection Act, the ICDPA creates several consumer rights: to know, to access, to correct, to delete, and to port data, as well as the ability to opt out of its processing/sale.

And it requires businesses, among other things, to provide a privacy notice and other disclosures, to obtain affirmative consent before processing "sensitive personal data," to conduct data protection impact assessments, and to enter binding contracts with third-party data processors to ensure that they, too, respect consumer privacy rights.

The ICDPA will be enforced exclusively by the Indiana attorney general. (It does not establish a private right of action.) In addition, it provides businesses with a 30-day cure period.

At the federal level, the House Committee on Energy & Commerce's Innovation, Data, and Commerce Subcommittee held a hearing on April 27th titled "Addressing America's Data Privacy Shortfalls: How a National Standard Fills Gaps to Protect Americans' Personal Information." It was the sixth Committee hearing on the topic of privacy thus far this legislative session.

In a joint statement, Committee Chair Cathy McMorris Rodgers (R – WA) and Subcommittee Chair Gus Bilirakis (R – FL) wrote that "[t]he Energy and Commerce Committee is building momentum this Congress towards enacting comprehensive national privacy and data security legislation."

Fittingly, in his opening statement, Subcommittee Chair Bilirakis acknowledged that the data privacy picture "only gets more complicated as fifty different states move towards their own data privacy laws, meaning an increasingly complicated and confusing landscape for consumers and for business."

Friday, March 31, 2023

Iowa Is State No. 6 to Pass a Privacy Statute

On March 28, Iowa Governor Kim Reynolds signed Senate File (SF) 262, "an Act relating to consumer data protection, providing civil penalties, and including effective date provisions." Following in the footsteps of California (here and here), Virginia, Colorado, Utah, and Connecticut, Iowa has become the sixth state to pass its own unique take on a comprehensive data privacy law.

With Congress still unable to agree upon the details of a national privacy framework, this most recent addition to the steadily expanding list of inconsistent state statutes further exacerbates compliance headaches for companies and adds to consumer confusion.

Laws in California and Virginia already are in effect. The start date for those in Colorado and Connecticut is July 1, 2023. Utah's statute becomes valid at the end of this year. And Iowa's SF 262 kicks in on January 1, 2025.

In other state-level privacy news, both California and Colorado recently finalized rulemaking proceedings arising from their respective comprehensive data privacy statutes:

  • On March 29, the California Office of Administrative Law approved the initial set of rules implementing the California Privacy Rights Act, also known as Proposition 24. Adopted by the California Privacy Protection Agency (CPPA), the first-of-its-kind state agency specifically dedicated to privacy, the rules became effective immediately. By statute, however, California's Office of Attorney General cannot initiate enforcement efforts until July 1. (Once officially processed, those rules, which substantively are unchanged from the drafts voted on by the CPPA in February, will be available here.)
  • On March 15, the Colorado Attorney General's Office announced that it had filed with the Colorado Secretary of State's Office final versions of its rules implementing the Colorado Privacy Act. Like the statute itself, those rules will go into effect on July 1.

At the federal level, meanwhile, the American Data Privacy and Protection Act, the first bill of its kind to make it out of congressional committee, remains in limbo. However, there have been two House Commerce Committee hearings on the topic of privacy thus far in 2023.

The first, entitled "Promoting U.S. Innovation and Individual Liberty through a National Standard for Data Privacy," was held by the Innovation, Data, and Commerce Subcommittee on March 1.

The second, a full Committee hearing entitled "TikTok: How Congress Can Safeguard American Data Privacy and Protect Children from Online Harms," took place on March 23.

In a media appearance shortly thereafter, Chair Cathy McMorris Rodgers (R-WA) stated that the testimony of TikTok CEO Shou Chew puts "more urgency on us passing a national data privacy law to protect [America] from the next technological tool or weapon that China may put together'" and that "[w]e need a national data privacy standard … and that's what Ranking Member Pallone and I have worked on and we're going to introduce this Congress because we need to take action."

Tuesday, October 25, 2022

Privacy Recap: Regulatory Developments in California, Colorado

As the promising-but-flawed American Data Privacy and Protection Act awaits a House floor vote and the revised deadline for comments on the FTC's highly problematic privacy Advance Notice of Proposed Rulemaking looms, state activity continues to fill the federal void.

In California, the only state where a comprehensive data privacy law has gone into effect, enforcement is underway – while, simultaneously, efforts to adopt rules implementing the Golden State's second privacy statute near the finish line. And in Colorado, the rulemaking process relating to its privacy law is just getting started.

In August, California Attorney General Rob Bonta announced a $1.2 million settlement with Sephora, Inc. regarding several alleged violations of the California Consumer Privacy Act (CCPA), which became valid law at the beginning of 2020.

According to the complaint, Sephora "did not tell consumers that it sold their personal information," "did not provide consumers with an easy-to find 'Do Not Sell My Personal Information' link," and did not configure its website "to detect or process any global privacy control signals, such as the 'Global Privacy Control' (GPC)."

As explained in the GPC website FAQs, the GPC "is a proposed specification designed to allow Internet users to notify businesses of their privacy preferences, such as whether or not they want their personal information to be sold or shared. It consists of a setting or extension in the user's browser or mobile device and acts as a mechanism that websites can use to indicate they support the specification."

Under the CCPA, the enabling of a universal opt-out mechanism such as the GPC has the same legal effect as clicking on a "Do Not Sell My Personal Information" link.

While the Sephora settlement is the first of its kind, it is by no means the only enforcement action undertaken by the California Attorney General's office. As noted in the Press Release, "[s]ince July 1, 2020, the Attorney General has issued notices to a wide array of businesses alleging noncompliance with the CCPA. Notices to cure have been issued to major corporations in the tech, healthcare, retail, fitness, data brokerage, and telecom industries, among others."

In addition, and as I detailed in "California Voters Approve the California Privacy Rights Act: A Detailed Analysis of Its Requirements and Impact," a November 2020 Perspectives from FSF Scholars, the Consumer Privacy Rights Act of 2020 (CPRA), which builds upon and modifies the CCPA, created the California Privacy Protection Agency (CPPA), the nation's first (and, at present, only) state agency dedicated to consumer privacy.

Once established, the CPPA assumed privacy-related rulemaking responsibilities from the office of the Attorney General. On May 27, 2022, the CPPA released draft CPRA regulations. Publication of a Notice of Proposed Rulemaking on July 8, 2022, formally started the process. The comment period closed on August 23, 2022.

On October 17, 2022, the CPPA released a modified draft of the CPRA regulations, as well as an explanation of the modified text. The CPPA Board will discuss, and potentially adopt some or all of the proposed rules, at virtual meetings this Friday and Saturday.

Per the CPPA's website, "[t]he proposed regulations (1) update existing CCPA regulations to harmonize them with CPRA amendments to the CCPA; (2) operationalize new rights and concepts introduced by the CPRA to provide clarity and specificity to implement the law; and (3) reorganize and consolidate requirements set forth in the law to make the regulations easier to follow and understand."

Colorado was the third state out of five so far – the others are California, Virginia, Utah, and Connecticut – to adopt a comprehensive data privacy statute. I summarized the major provisions of the Colorado Privacy Act (CPA) in an April 2021 post to the Free State Foundation's blog.

The CPA, which is scheduled to go into effect on July 1, 2023, authorizes the Colorado Attorney General to craft rules generally "for the purpose of carrying out" the CPA as well as a specific rule regarding "the technical specifications for one or more universal opt-out mechanisms that clearly communicate a consumer's affirmative, freely given, and unambiguous choice to opt out of the processing of personal data for purposes of targeted advertising or the sale of personal data."

On October 10, 2022, Colorado Attorney General Phil Weiser's office published a Notice of Proposed Rulemaking (NPRM). Comments are due on or before February 1, 2023 – but earlier deadlines apply if they are to "inform the stakeholder meetings" scheduled for November 10, 15, and 17, or are to be considered at the rulemaking hearing on February 1, 2023.

Specific topics addressed in the NPRM include: the substantive requirements for privacy notices, the scope of the consumer rights established by the CPA and the processes by which those rights are exercised, specifications for universal opt-out mechanisms, the duties of businesses ("controllers") that collect personal information, and the method by which consent is obtained ("including the prohibition against obtaining agreement through the use of Dark Patterns").

Tuesday, March 08, 2022

Utah "Nearly Certain" to Become Fourth State to Pass a Privacy Law

Any day now, Utah almost certainly will become the fourth state to enact comprehensive data privacy legislation. As I have written previously, in a series of posts to the Free State Foundation's blog and Perspectives from FSF Scholars, Congress bears the increasingly urgent responsibility to pass a federal privacy statute, one that preempts state laws, rejects a private right of action, and establishes a single set of clear rules that businesses can abide and consumers can understand.

Even President Biden, in his State of the Union Address, acknowledged the need for Congress to break the privacy logjam.

The California Consumer Privacy Act and the California Privacy Rights Act. The Virginia Consumer Data Protection Act. The Colorado Privacy Act. Four laws in three states, each imposing a unique set of rights and responsibilities on the border-defying Internet.

In "Inconsistent State Data Privacy Laws Increase Confusion and Costs," a March 2021 Perspectives from FSF Scholars, I explained the headaches that result. Companies must either (1) take high-risk pains to associate accurately each customer interaction with the appropriate state, or (2) craft one-size-fits-all compliance programs that reflect the "greatest hits" imposed by the growing list of states taking steps to fill the federal void. Consumers, meanwhile, are left to try to make sense of these overlapping and contradictory state-specific regimes on their own.

The Utah Consumer Privacy Act is poised to further complicate this already untenable situation. Based upon, but by no means identical to, the Virginia Consumer Data Protection Act, it was passed unanimously by both the Utah Senate and House of Representatives. Last Friday, it landed on the desk of Governor Spencer Cox, who is "nearly certain" to sign it into law. Assuming he does, it will become effective at the end of next year.

Similar to the other state privacy laws already enacted, the Utah Consumer Privacy Act (Act) would establish rights for consumers (to know what personal data is collected, to access or delete that information, to opt out of the collection, use, and sale of personal data for certain purposes, and so on) and responsibilities for covered entities (such as obligations to provide adequate notice to consumers, to safeguard collected personal data, and to respond within a defined window to consumer requests).

However, and as is already the case regarding the laws passed in California, Virginia, and Colorado, the specifics of the Act in many instances are one of a kind.

For example, and subject to exceptions, the Act would apply to a "controller" (defined as "a person … who determines the purposes for which and the means by which personal data is processed") or "processor" (defined as "a person who processes personal data on behalf of a controller") who:

  • Does business in Utah or targets state residents with a product or service;
  • Generates at least $25 million in annual revenues; and
  • Either (a) accesses the personal data of at least 100,000 consumers in a year or (b) derives more than half of its gross revenues from the sale of personal data and accesses the personal data of more than 25,000 consumers.

In the March 2021 Perspectives referenced above, I pointed out that applicability is one of the many ways in which the various state laws deviate from one another – and thereby complicate matters for all involved: "As an initial matter, these bills establish different minimum thresholds – including annual gross revenue amounts and number of individuals, or individuals, households, and devices, subject to data collection – for a business to be deemed covered."

Other ways in which the Act would differ from other state laws:

  • The Act would create the consumer right to delete personal information – but only that data in fact provided by the consumer, not data the covered entity has obtained from other sources.
  • It would define "sensitive data," a subset of personal data, to include information such as racial and ethnic origin, religious beliefs, sexual orientation, medical history, and genetic, biometric data, and geolocation data. Covered entities would be required to provide notice and an opportunity to opt-out of the collection and/or use of "sensitive data" – rather than requiring that consumers first opt-in.
  • It would define "sale" in a manner that, unlike, say, the California Privacy Rights Act, does not include "other monetary consideration."

To be clear, I am not saying these variations are good or bad – just complicating.

Finally, I want to point out approvingly that the Act states unambiguously that "[a] violation of this chapter does not provide a basis for, nor is a violation of this chapter subject to, a private right of action under this chapter or any other law."

Instead, the Act would task the Department of Commerce's Division of Consumer Protection with investigating consumer complaints. The Office of the Attorney General, in turn, would have exclusive enforcement responsibility. Covered entities would be provided with a 30-day right to cure, after which penalties up to $7,500 per violation could be imposed.

Friday, March 12, 2021

Florida Vies for Bronze in Race to Create Patchwork of State Data Privacy Laws

Florida seems likely to become the third state, after California and Virginia, to adopt a comprehensive data policy law.

The California Consumer Privacy Act (CCPA) has been in effect since the beginning of 2020. Given the inability of Congress thus far to reach consensus on federal legislation, the CCPA has served as the de facto U.S. data privacy law for over a year. Last November, voters approved the California Privacy Rights Act (CPRA), which will expand upon the CCPA in numerous ways at the beginning of 2023.

On March 2, Virginia Governor Ralph Northam added the second square to the quilt when he signed into law the Consumer Data Privacy Act, the details of which I described in a February 5 post to the FSF Blog. Like the CPRA, it becomes effective on January 1, 2023.

A number of additional states, including Minnesota, New York, Oklahoma, and Washington State, are considering comprehensive data privacy legislation. Florida, however, appears poised to be the next to act.

On February 15, Florida House of Representatives member Fiona McFarland introduced House Bill (H.B.) 969. The draft legislation, which has the support of Governor Ron DeSantis and House Speaker Chris Sprowls, on Wednesday received unanimous committee approval upon its first reading.

H.B. 969 would establish a number of consumer data privacy rights: the right to know what personal information businesses collect; rights to receive a copy of, correct, and delete that data; and the right to opt-out of its sale to third parties. It also would prohibit discrimination against a consumer who exercises any of these rights.

In addition, H.B. 969 would impose a requirement to delete collected data "after satisfaction of the initial purpose for collecting or obtaining such information, or after the duration of a contract, or 1 year after the consumer's last interaction with the business, whichever comes first."

The Department of Legal Affairs would be responsible for enforcing the provisions of H.B. 969. However, businesses first would be afforded a 30-day opportunity to cure.

Of perhaps greatest concern, H.B. 969 also would establish a private right of action in connection with a data breach. Affected consumers could pursue both (1) up to $750 in statutory damages or actual damages, whichever is greater, and (2) injunctive or declaratory relief.

If passed, H.B. 969 would go into effect at the beginning of next year.

Be on the lookout for additional commentary from the Free State Foundation on state data privacy laws in the coming days.

Friday, February 05, 2021

Virginia's Consumer Data Protection Act Soon Could Become Law

Virginia is poised to become the second state to adopt a data privacy law. California led the way, first with the passage in 2018 of the California Consumer Privacy Act (CCPA) and, more recently, via voter approval in the November 2020 election of Proposition 24, the California Privacy Rights Act (CPRA).

The Virginia Consumer Data Protection Act (CDPA) includes the following key provisions:

  • New Consumer Private Rights: The CDPA grants consumers the right to access, the right to amend, and the right to delete personal data; the right to data portability; and the right "[t]o opt out of the processing of … personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer."
  • Definition of "Personal Data": The CDPA defines "personal data" as "any information that is linked or reasonably linkable to an identified or identifiable natural person. 'Personal data' does not include de-identified data or publicly available information."
  • Definition of "Sensitive Data": "Sensitive data," for which consumer or parental opt-in consent must be obtained before it is processed, is defined as a subset of "personal data" that includes (1) information "revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status;" (2) "[t]he processing of genetic or biometric data for the purpose of uniquely identifying a natural person;" (3) "[t]he personal data collected from a known child;" and (4) "[p]recise geolocation data."
  • Covered Entities: The CDPA "applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data."
  • Enforcement: The CDPA exclusively authorizes the state attorney general to enforce its provisions via civil actions. There is no private right of action and covered entities are entitled to a 30-day cure period.

On February 3, the Virginia Senate unanimously passed SB 1392, identical companion legislation to HB 2307, which easily cleared the House of Delegates by a 89-9 vote on January 29. Should Governor Ralph Northam sign the bill into law, it would become effective on January 1, 2023.

I have argued in posts to the Free State Foundation Blog as well as Perspectives from FSF Scholars that what is needed is a single set of privacy rules that apply nationwide and preempt state laws. In the absence of federal legislation, however, we continue to see activity at the state level.

Additional states currently considering data privacy legislation include Washington, New York, and Oklahoma.

Friday, October 23, 2020

Proposed Revisions to California's Privacy Law Create Additional Unwanted Uncertainty, Underline Need for Federal Legislation

The online privacy saga continues. The latest chapter: yet another round of proposed changes to the rules implementing the California Consumer Privacy Act (CCPA), an unprecedented and overreaching set of restrictions effectively imposed throughout the country by a single state.

Internet traffic is interstate. Rarely is it confined within the boundaries of any single state, even one that happens to be the largest by population, the fifth biggest economy in the world, and the home of many major online companies. Congress therefore is the appropriate legislative body to craft the privacy rules of the road for virtual interactions between consumers and businesses.

In the absence of federal action, however, California's privacy law as a practical matter has filled the void, as many companies find it easier and more cost-effective to comply with the CCPA nationwide than to try to implement processes to identify who is covered and who is not. Of equal concern, efforts to implement the CCPA have led to uncertainty and confusion. As a result, compliance has been rendered unnecessarily and unreasonably more difficult and expensive.

As I have explained in a series of posts to the Free State Foundation blog and in a number of Perspectives from FSF Scholars, federal Internet privacy rules ideally should include the following:

  • Consistent treatment of all rivals irrespective of outdated regulatory classifications
  • A national approach that preempts state laws
  • Exclusive enforcement by a single agency (that is, the FTC) and state attorneys general (in other words, no private right of action)
  • A flexible, case-by-case approach to alleged violations rather than overly proscriptive ex ante rules
  • An "opt-out" model with respect to non-sensitive personal information
  • An acknowledgement that consumers do value ad-supported goods and services

Bipartisan efforts in Congress, in particular the Senate, have managed to find common ground on a number of these issues. Two, however, at present serve as insurmountable hurdles.

The first is state preemption. As I note above and addressed in detail in "California's Heavy-Handed Approach to Protecting Consumer Privacy: Exhibit A in the Case for Federal Preemption," an October 2019 Perspectives from FSF Scholars, a "patchwork" of state and local privacy laws is incompatible with the inherently interstate nature of the Internet.

Consumers expect a common set of rules to apply no matter where they, or the online businesses with which they transact, may be located. Similarly, it would be unreasonable to require online businesses to comply with different requirements based upon (potentially inconsistent) geographic criteria: a customer's real-time location, state of residence, Internet Protocol address, or some other consideration. Technical and administrative efforts to make such identifications would be an unjustified waste of substantial resources.

The second is a private right of action. Without question, as a general matter enforcement mechanisms serve an important purpose. They provide the teeth that motivate compliant behavior, prevent violators from profiting from their misdeeds, generate clarifying case law, and compensate those who have been harmed.

Particularly in the privacy context, however, a private right of action is ill-suited to the achievement of these goals. Individual privacy-related injuries often go undetected. When they do draw attention, the identity of the perpetrator may not be known. Actual damages, necessary for a case to proceed, can be difficult to calculate. And statutory damages often lead to the unintended and undesirable result where plaintiffs' attorneys recoup legal fees but their clients receive little, especially in the case of class actions.

Nevertheless, the fact remains that members of Congress at present are unable to achieve consensus on either of these issues. The passage of federal privacy legislation therefore appears unlikely at this time. In the meantime, online businesses are subject to the CCPA and its evolving implementing rules.

Drafted in only "a matter of days" and signed into law on June 28, 2018, the CCPA:

  • Created new consumer privacy rights (the right to know what data businesses collect, the right to require businesses to delete data, the right to opt-out of the sale of information, and the right to non-discrimination for exercising these rights)
  • Imposed substantial compliance obligations, including detailed notice and record-keeping requirements, upon businesses
  • Authorized the California Attorney General to impose civil penalties for violations
  • Established a private right of action qualified by a right to cure.

The CCPA also delegated to the California Attorney General's office responsibility for promulgating rules defining its precise scope. The devil is in the details, as they say, and until final rules were in place, businesses unavoidably lacked confidence in the adequacy of their compliance efforts. Unfortunately, Attorney General Xavier Becerra did not release initial draft rules until October 11, 2019, less than three months before the CCPA became effective on January 1, 2020.

Worse, the rulemaking process dragged on for months, beyond both the start of the new year, at which point businesses became subject to the provisions of the CCPA, and July 1, when enforcement of the statute itself began. After a great deal of administrative drama, the Office of Administrative Law (OAL) on an expedited basis approved final regulations on August 14. The rules became effective immediately.

Less than two months later, on October 12, AG Becerra proposed a third set of edits to those rules. As a result, businesses once again are faced with an uncertain future.

One such change relates to "do not sell my personal information" requests: businesses would be required to "provide notice by an offline method that facilitates consumers' awareness of their right to opt out." By way of example, notice could be given verbally during an interaction via phone or, if at a physical location, on paper forms used to collect personal information.

Another update would require that the methods by which businesses accept opt-out requests "be easy for consumers to execute and shall require minimal steps to allow the consumer to opt out. A business shall not use a method that is designed with the purpose or has the substantial effect of subverting or impairing a consumer's choice to opt out."

Comments on these proposed changes are due on or before October 28.

While perhaps relatively minor, the fact remains that these contemplated revisions would require businesses to expend additional resources to update their compliance programs.

The ink is not yet dry on the long-awaited "final" rules. The full extent of the COVID-19 pandemic's economic impact is unknowable. And the presence of the California Privacy Rights Act of 2020 (aka the CCPA version 2.0) on the November ballot threatens still more change and uncertainty.

Now is a particularly inopportune moment to impose additional burdens. But on the bright side, this most recent development out of California might serve as motivation for Congress to pass a federal privacy law.

Friday, August 28, 2020

Rules Implementing California's Privacy Law Now in Effect

In an August 14 press release, California Attorney General Xavier Becerra announced that, at long last, final rules implementing the California Consumer Privacy Act (CCPA) had been approved, with some "unexpected" revisions, by the Office of Administrative Law (OAL). They became effective immediately.

As I wrote previously on the Free State Foundation blog, at one point it seemed likely, at another conceivable, that administrative hurdles would delay those rules until October 1.

January 1 was the effective date of the CCPA, but the AG was barred from enforcing its provisions until July 1. Press reports indicate that his office began notifying businesses of non-compliance on day one.


The CCPA affords businesses receiving such notices 30 days to cure alleged violations before formal enforcement activity, whether a confidential investigation or a lawsuit, can commence. Dozens of such investigations reportedly are underway. To my knowledge, however, to date no suits have been filed.

According to Stacey Schesser, Supervising Deputy AG, that first round of notices was driven by complaints received from consumers, targeted online businesses operating across a range of industries, and focused on those that allegedly either (a) had not made available mandatory disclosures, or (b) had failed to add a "Do Not Sell My Personal Information" link to their websites.

Previously, the Attorney General had indicated his intention to prioritize violations impacting minors and other vulnerable groups.

Now that the implementing rules are in effect, we should expect the AG's office to begin enforcing them, as well.

In an April 30 Perspectives from FSF Scholars, I noted that a group of over 60 affected businesses in March wrote to AG Becerra requesting that he forbear from enforcement until next January in light of the serious economic fallout from the COVID-19 public health crisis. He declined, and in the press release announcing OAL's approval of the rules, argued instead that "[a]s we face a pandemic of historic proportions, it is particularly critical to be mindful of personal data security."

Sunday, June 28, 2020

Privacy Roundup: CPRA Qualifies for CA Ballot, Comcast Enables Encrypted DNS

Two quick updates on privacy topics I've addressed recently:
First, California Secretary of State Alex Padilla announced on June 25 that the California Privacy Rights Act (CPRA) will appear on the ballot this November.
According to Californians for Consumer Privacy, the organization behind the ballot initiative, polling indicates that voters are likely to approve the CPRA.
For a critique of what many refer to as the CCPA 2.0, please check out my May 27 Perspective from FSF Scholars, "California Privacy Regulation Must Account for the COVID-19 Crisis."


Second, that same day Mozilla and Comcast announced that the latter will be the first ISP to provide Domain Name System (DNS) over Hypertext Transfer Protocol Secure (HTTS) (DoH) encryption to users of the Firefox browser.
According to the Press Release, "DoH helps to protect browsing activity from interception, manipulation, and collection in the middle of the network by encrypting the DNS data."
In an April 9 Free State Foundation Perspectives, "Maine's ISP-Only Privacy Law Will Not Protect Consumers," I explained how the increasing use of DoH, and HTTPS encryption generally, limit ISPs' ability to "see" what subscribers do online – and how edge providers, by contrast, have far greater access to online personal information.
This voluntary action by Comcast not only enhances subscriber privacy, it also undermines further the proffered justifications for the Maine statute.

Friday, June 05, 2020

Privacy Recap: Another CCPA Update, Another COVID-19 Bill

Another round of privacy developments:

First, I reported last Saturday that "it ... appears likely that rules implementing the California Consumer Privacy Act (CCPA) will not become effective until October 1." Attorney General Xavier Becerra had not yet submitted those rules to the Office of Administrative Law (OAL), and time was almost up.

It's a good thing that I qualified that statement, because on Monday – the deadline was extended from May 31, a Sunday, to Monday, June 1 – the AG beat the buzzer, seeking approval, and requesting expedited review, of the same version of rules on which his office sought public comment nearly two months ago.

I find it interesting that the request for expedited review comes right out and acknowledges that, "[o]nce final regulations are adopted, the Attorney General will enforce the regulations that establish procedures to facilitate new consumer rights under the CCPA and provide guidance to businesses for how to comply." I couldn't have said it better myself.

If the OAL grants that request and completes its review within 30 days, the rules still could go into effect on July 1, the same day on which the AG in a June 2 press release confirmed his intention to commence CCPA enforcement. Stay tuned.

Second, yet another coronavirus-specific privacy bill has been introduced. Senate Republicans on the Commerce Committee unveiled the COVID-19 Consumer Data Protection Act of 2020 (CCDPA) on May 7. Congressional Democrats responded with the Public Health Emergency Privacy Act (PHEPA) on May 14. A bipartisan group of Senators completed the trilogy on June 1 with the Exposure Privacy Notification Act (EPNA).

Sponsored by Senators Maria Cantwell (D – WA), ranking member of the Commerce Committee, and Bill Cassidy (R – LA), and co-sponsored by Senator Amy Klobuchar (D – MN), the EPNA, as its title suggests, focuses on the notices provided via contract tracing apps and similar technological approaches  to containing the spread of the virus ("automated exposure notification services").

Among other things, the EPNA would:

  • Require "opt-in" consent – and allow consumers to revoke that consent at any time;
  • Require app developers to collaborate with public health officials;
  • Limit notifications to medically-authorized diagnoses of infectious diseases;
  • Allow participating consumers to determine whether their diagnoses are included in such notifications;
  • Limit data collection and use to that which is reasonably necessary for public-health purposes;
  • Ban any commercial use of that data;
  • Prohibit, with certain exceptions, the transfer of that data;
  • Create a right to delete – and allow consumers to exercise that right at any time;
  • Require, on a rolling basis, data deletion after 30 days;
  • Prohibit discrimination based upon that data or a refusal to participate;
  • Require minimum data security practices including breach notifications;
  • Provide for oversight and reporting by the Privacy and Civil Liberties Oversight Board;
  • Empower the FTC and state attorneys general to enforce its provisions;
  • Authorize the FTC to impose civil penalties for first-time violations; and
  • Preserve (that is, not preempt) state laws.

Saturday, May 30, 2020

Privacy Recap: Updates on CCPA Regulations, CPRA Ballot Initiative; Congressional Democrats Introduce Rival COVID-19 Bill

Below I summarize a few recent developments of note in the privacy space:

First, it now appears likely that rules implementing the California Consumer Privacy Act (CCPA) will not become effective until October 1. As you may recall, enforcement of the CCPA, which became law on January 1, is set to begin on the first of July. However, rules being drafted by the Attorney General's office will not become final by that date unless they are submitted to the Office of Administrative Law for review by May 31 (that is, tomorrow).

I have argued repeatedly that, especially in light of current economic circumstances, Attorney General Becerra should delay CCPA enforcement until affected businesses have been provided sufficient opportunity to assess, and come into compliance with, finalized versions of these implementing rules. Things could change in the next month, but so far he has rejected requests for additional time.



Second, privacy advocates' attempt to add the California Privacy Rights Act of 2020 (aka the CCPA 2.0) to the November ballot has cleared its first procedural hurdle. CA Secretary of State Alex Padilla recently announced that Californians for Consumer Privacy submitted significantly more signatures than required: 930,942 versus 623,212. Per state guidelines, County election officials next will attempt to verify a sufficient number of those signatures by June 25 to qualify the initiative.

Third, in a May 12 blog post, I provided a summary of the COVID-19 Consumer Data Protection Act of 2020 (CCDPA), federal privacy legislation introduced by five Republican members of the Senate Commerce Committee. The CCDPA would regulate the use of personal data to fight the spread of the coronavirus through digital contact tracing and similar techniques. A few days later, five Democrats in the Senate and House — Senators Richard Blumenthal (CT) and Mark Warner (VA) and Representatives Anna Eshoo (CA), Jan Schakowsky (IL), and Suzan DelBene (WA) — countered with their own pandemic-specific bill, the Public Health Emergency Privacy Act (PHEPA).

Similar to the CCDPA, the PHEPA would require covered entities to:

  • Provide adequate notice;
  • Obtain "opt-in" consent prior to collecting "emergency health data" and provide a means to revoke that consent at a later date;
  • Limit the collection and use of emergency health data to that which is necessary and proportionate for a "good faith public health purpose;"
  • Ensure that that data is accurate and provide consumers an opportunity to correct inaccurate information;
  • Implement reasonable data security practices; and
  • Stop using or maintaining emergency data after the end of the current crisis.

Also like the CCPDA, the PHEPA would empower the FTC and state attorneys general to enforce its provisions.

However, the PHEPA differs from the CCDPA in two significant respects. One, it includes a private right of action. Consumers would be able to seek relief between $100 and $1,000 per negligent violation and between $500 and $5000 per reckless, willful, or intentional violation. I presented a number of arguments against a private right of action for privacy violations in a January 21 FSF Perspectives

Two, it expressly does not preempt more stringent state laws. In an October 28, 2019, piece for the Free State Foundation analyzing one such law – as it happens,  the CCPA – I explained why preemptive federal privacy legislation would be preferable to a patchwork of state laws.

Other provisions unique to the PHEPA include:

  • A requirement that the Secretary of Health and Human Services, in consultation with the United States Commission on Civil Rights and the FTC, provide Congress with regular reports on the civil rights impact of the use of emergency health data to fight the COVID-19 pandemic; and
  • A prohibition on the use of that data "to deny, retract, or interfere with" a consumer's right to vote.

Monday, April 13, 2020

Will Enforcement of California's Privacy Law Precede Final Rules?

Between Easter and quarantine baking, eggs are trending. But do they – or chickens – come first? No one knows for certain. By contrast, the sequential order of rules and enforcement is, or at least should be, noncontroversial. Step one, establish the do’s and don’ts. Step two, target the violators. Not when it comes to the California Consumer Privacy Act (CCPA), however.

The CCPA, which became effective on the first of January, includes language that, on its face, appears to defer the commencement of enforcement. Except that it does no such thing. California Attorney General Xavier Becerra may not initiate enforcement “until six months after the publication of the final regulations issued pursuant to this section or July 1, 2020, whichever is sooner.”


No, that’s not a typo. The statute contemplates that the AG might bring action before his office has provided those subject to the CCPA with the necessary clarity that only finalized rules can afford. This is particularly problematic given that those rules will spell out actions that businesses must take in order to be in compliance. Specifically, they will define, among other things, the categories of personal information covered, the processes for submitting and responding to opt-out requests, and the manner in which notices must be provided.

Making matters worse, the AG’s office has indicated that it will consider taking retroactive action – that is, pursuing companies for alleged violations that occur prior to July 1.

Businesses cannot comply with rules that do not yet exist. Nevertheless, and even though the CCPA was adopted back in 2018, the AG’s office did not publish proposed rules until October 11, 2019 – virtually assuring that they would not be finalized by this July. Since then, it has issued two sets of modified rules, on February 10 and March 11. Comments on the latter were due just over two weeks ago. What the next steps are (yet another round of edits?), and how long they might take, currently are not known.

Then, on March 30, California Governor Gavin Newsom issued Executive Order N-40-20, which, in light of the impact of the Coronavirus-related State of Emergency that he declared on March 4, extends “deadlines …related to the filing, refiling, certification and/or review of regulations and emergency regulations … for a period of 60 calendar days to allow state agencies additional time to finalize regulatory changes pursuant to the Administrative Procedure Act.”

As a practical matter, this effectively ensures that, come July 1, entities covered by the CCPA will find themselves in regulatory no-man’s land.

On March 20, a group of 66 trade associations, companies and other organizations wrote to Attorney General Becerra asking that he forbear from enforcing the CCPA until January 1, 2021. They based their request on both the incomplete status of the rules and the general impact of the COVID-19 pandemic.

An advisor to the AG, responding to a request for comment by Forbes, wrote in an email that “‘[r]ight now, we’re committed to enforcing the law upon finalizing the rules or July 1, whichever comes first…. We’re all mindful of the new reality created by COVID-19 and the heightened value of protecting consumers’ privacy online that comes with it. We encourage businesses to be particularly mindful of data security in this time of emergency.”

As Dan Jaffe, Executive Vice President of Government Relations for the Association of National Advertisers (one of the signatories to the forbearance letter mentioned above) recently blogged, “[e]nforcing last minute regulations without giving companies time to adapt their practices accordingly is not right. It is not fair for consumers who expect standard, legally compliant responses from business. It is not fair for businesses who deserve clarity in regard to their obligations under the CCPA.”

Thursday, November 21, 2019

California's Privacy Law: Recent Developments Underscore the Need for Preemptive Federal Law

In an October 2019 Perspectives, I argue that the California Consumer Privacy Act of 2018 (the "CCPA") violates sound principles of online consumer privacy regulation and threatens to reduce consumer welfare – and not just within that state's borders. Given the size of California's economy and the prominent role it plays in the tech and information services sectors, the harmful impact of the CCPA could be felt across the country, if not the world. It is therefore incumbent upon Congress to adopt a federal privacy law that preempts California's attempt to establish de facto rules of the road for the nationwide digital services marketplace.
A recent announcement by a major technology company highlights my concerns.
In a blog post on November 11, 2019, Julie Brill, Microsoft's Corporate Vice President for Global Privacy and Regulatory Affairs and Chief Privacy Officer, announced that it "will extend CCPA’s core rights for people to control their data to all our customers in the U.S." Other companies undoubtedly will follow suit, for a number of reasons.

First, it may be more cost efficient to establish and maintain a single, national compliance program than one for the state of California and another for the rest of the country.
Second, consumers reasonably expect that a single set of online protections will apply regardless of where they, or the company with which they are transacting, happen to be.
Third, online traffic flows inherently are interstate in nature. By design, the route that an Internet Protocol data packet travels is influenced by real-time network congestion levels. Even between the same two end points, that path – and the state(s) that it passes through – can vary from one moment to the next. To the extent that targeted compliance requires the accurate identification of a consumer's location, companies may choose to apply the CCPA nationwide rather than risk a violation solely due to technical error.
A new federal privacy law could sidestep these issues – but only if it preempts state action. Not all lawmakers agree, however. In fact, two Democratic members of the House introduced legislation on November 5, 2019 that would make the situation far worse.
The Online Privacy Act, drafted by Silicon Valley Representatives Zoe Lofgren and Anna Eshoo, proposes its own highly proscriptive set of privacy rules. Among other things, it would: create consumer rights that are similar, but not identical, to those found in the CCPA; require companies to obtain explicit consent (i.e., "opt-in") before disclosing or selling personal information; prohibit the use of web traffic information as the basis for ads; create a new federal bureaucracy – the 1,600-employee-strong Digital Privacy Agency – rather than leverage the experience and expertise of the Federal Trade Commission; and establish a private right of action for individuals.
The most significant problem with the Online Privacy Act, however, is that it would impose requirements at the federal level – but would fail to preempt state lawsDe facto regulation of the nationwide digital services marketplace pursuant to the California model would be bad. The "patchwork" that could result if other states enact their own laws would be worse. Worst of all, however, would be an additional layer of burdensome federal regulation on top of (likely inconsistent, and certainly problematic) state law(s).
The effective date of the CCPA is right around the corner. Absent congressional action, on January 1, 2020, California's ill-conceived approach as a practical matter may become the privacy law of the land. Those members of Congress who recognize the need for a coherent, nationwide approach to online privacy oversight should act promptly to preempt not just this inconsistent state law, but also rival proposals at the federal level that threaten to exacerbate the situation.

Wednesday, September 20, 2017

California Privacy Act Fails to Pass

Last week, the “California Privacy Act,” modeled after the FCC’s Broadband Privacy Order, failed to make it to the floor before California’s 2017 legislative session ended. This is not the first time a state tried to pass problematic privacy legislation. The Maryland State Senate proposed a similar bill in April 2017 and it also failed to pass. As I stated in an April 2017 blog, state-level broadband privacy laws raise many practical questions about enforcement efforts. Ultimately, privacy jurisdiction should return to the FTC, where privacy matters can be adjudicated on a case-by-case basis.